I think the English language aspect is much more interesting and difficult/impossible to prevent.
An inside look at NSA tactics, techniques and procedures from China's lens
21–30 of 76 posts
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#22I originally came here to comment how crazy it seems that DoD employees at NSA cannot be bothered to cover their tracks by working nonstandard hours/holidays (obviously Mil & Intel folks do this, they even get deployed!). But the thought occurred to me that attribution to NSA was likely a desired outcome here (“We can hack you too”) and there are probably many people at NSA working nonstandard hours/days to prevent a…
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#23Earlier quoted context omitted.
Assuming they mean Solaris, it's still technically maintained, at least in the Oracle sense (of both "technically" and "maintained").
I assumed that much, SunOS is pretty ancient, last version was what, in early 1990s? Though, Solaris still would report a SunOS 5.$solarisver version or something like that. So I guess we can say it is a "SunOS" box if we wanted to.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#24I or anyone outside obviously cannot verify the technical details. However, the above statement struck as particularly uninformed. As any engineer in East Asia can tell you, there is nothing especially collaborative about tech in Confucian culture; if anything, the engineers in that region admire the free speech and discussion traditionally prized in the Western culture. Calling Chinese political framework, especially in the context of national security, conducive to open public discussion was quite ironic to see.
Edit: the punchline is this. If a friend who is always secretive and deceptive about his personal life is suddenly openly discussing his life, what does that say about the details he just disclosed and/or the situation he is currently in?
source: I regularly work with engineers from that culture and studied relevant geopolitics.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#25> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays. Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays. > Two zero-days were used to breach any company with SunOS-exposed system…
>A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA It seems like such a lapse in tradecraft that, absent other indicators, I would just assume it's a crude false flag attempt.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#26Earlier quoted context omitted.
The same strategy is used to attribute attacks against US based targets by Russian, N.Korean and Iranian and other state or state sponsored actors. Time of day, holidays, etc. are (in tandem with other evidence) considered to be surprisingly reliable. If I were in charge of things I'd like to think that this sort of thing would be the first step I'd take to cover my tracks, but I still hear cyber security firms using…
The type of work the people working at an APT do, is mainly office work, while it still is very much "hands-on-keyboard" work (so you cannot set an action to automatically occur when nobody is checking the results in the middle of the night). You might want to try shuffling this up when you are in charge, but your (usually highly skilled and expensive) employees probably don't want to be working weird shifts all the…
EDIT: Huh, I guess sometimes it is like the movies: > One of the frameworks used by TAO that was forensically uncovered during the incident named “NOPEN” requires human operation. As such, a lot of the attack required hands-on-keyboard and data analysis of the incident timeline showed 98% of all the attacks occurred during 9am – 16pm EST (US working hours).
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#27I originally came here to comment how crazy it seems that DoD employees at NSA cannot be bothered to cover their tracks by working nonstandard hours/holidays (obviously Mil & Intel folks do this, they even get deployed!). But the thought occurred to me that attribution to NSA was likely a desired outcome here (“We can hack you too”) and there are probably many people at NSA working nonstandard hours/days to prevent a…
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#28I'm guessing this is so when they do data exfiltration (and hosted MITM) it's not sending a ton of data to a single server, but spreads them out.
> SECONDDATE: This tool was allegedly used by TAO (NSA) to hack into the office intranet of the University. Attribution of SECONDDATE was discovered through collaboration with other industry partners. They found thousands of network devices running this spyware – where the communications went back to NSA servers located in Germany, Japan, South Korea and Taiwan. This tool was used to redirect user traffic to the FOXACID platform.
> SECONDDATE – Backdoor installed on network edge devices such as gateways and border routers to filter, and hijack mass amounts of data in a MiTM. This was placed on the border routers of the University to hijack traffic to redirect to NSA’s FOXACID platform.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#29Earlier quoted context omitted.
The type of work the people working at an APT do, is mainly office work, while it still is very much "hands-on-keyboard" work (so you cannot set an action to automatically occur when nobody is checking the results in the middle of the night). You might want to try shuffling this up when you are in charge, but your (usually highly skilled and expensive) employees probably don't want to be working weird shifts all the…
I have a hard time imagining these APT attacks are manual at the keyboard typing. That seems like an invention for entertainment whereas I'd expect reality to be "run script & establish an ongoing backdoor" or "run script & perform attack". You might need on-call to flag if anything has gone wrong, but I'd have a hard time imagining the entire team is involved for that so the cost of paying extra for an on-call is qu…
You wouldn't spend hundreds of thousands of dollars on large scale attacks with lots of (temporary) infrastructure and planning to then yolo it at the last minute and hope that everything goes well and you have the results back when you come back on Monday.